CVE-2023-7008: Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Other sources
systemd is vulnerable to a man-in-the-middle attack, caused by a flaw with able to accept records of DNSSEC-signed domains even when they have no signature. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to manipulate records.
— IBM
systemd-resolved accepts records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7008?
CVE-2023-7008 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2023-7008?
To fix CVE-2023-7008, update to systemd versions higher than 25 or apply any available patches.
What software is affected by CVE-2023-7008?
CVE-2023-7008 affects systemd version 25 and certain versions of IBM MQ Operator and supplied MQ Advanced container images.
Can CVE-2023-7008 be exploited remotely?
Yes, CVE-2023-7008 can potentially be exploited remotely by attackers who can manipulate DNS records.
What potential impact does CVE-2023-7008 have on my system?
The impact of CVE-2023-7008 can include unauthorized access to sensitive data and manipulation of DNS records leading to further attacks.